Executive brief
A security vulnerability in the Zoom Workplace VDI Plugin for Windows could allow a person with existing access to a computer to gain higher-level administrative privileges. This plugin is typically used in virtual desktop environments to optimize video conferencing performance. If exploited, an attacker could gain full control over the local system, potentially leading to unauthorized software installation or access to sensitive data.
Technical details
The vulnerability is classified as External Control of File Name or Path (CWE-73) within the Zoom Workplace VDI Plugin Windows Universal Installer. It occurs when the installer or plugin component fails to properly validate or restrict file paths provided by a user, allowing an attacker to reference resources in unauthorized locations. An authenticated local attacker with low privileges can exploit this flaw to execute code or manipulate system files with higher privileges (Escalation of Privilege). The issue is resolved in version 6.6.11 and later.
Affected products
- Zoom Workplace VDI Plugin Windows Universal Installer before 6.6.11
Timeline
- 2026-05-12: advisory: Initial publication of ZSB-26007 by Zoom
- 2026-05-13: disclosed: CVE published to NVD